Home Blog Page 392

Russian hackers targeted 21 US states in 2016 prez polls: DHS

US Elections

The Department of Homeland Security (DHS) on Friday, September 22, notified 21 states that were targeted by Russian hackers to sway the 2016 U.S. presidential elections in favor of Donald Trump.

The 21 states that came under the hackers’ radar were Alabama, Alaska, Arizona, California, Colorado, Connecticut, Delaware, Florida, Illinois, Iowa, Maryland, Minnesota, North Dakota, Ohio, Oklahoma, Oregon, Pennsylvania, Texas, Virginia, Washington, and Wisconsin.

In most of the targeted states, hackers were engaged in preliminary activities like scanning. However, it is not known if the attempts were successful in all the states.

Bob Kolasky, the acting DHS deputy undersecretary for the National Protection and Programs Directorate, told The Washington Post, “We heard feedback from the secretaries of state that this was an important piece of information”, while adding “we agreed that this information would help election officials make security decisions.”

Senate Select Committee on Intelligence Vice Chairman Sen. Mark R. Warner, D-Va., said in a statement that he was “relieved that DHS has acted upon our numerous requests and is finally informing the top elections officials in all 21 affected states that Russian hackers tried to breach their systems in the run up to the 2016 election.”

In August this year, Reuters reported that the U.S. intelligence agencies have concluded that the Kremlin orchestrated an operation that included hacking and online propaganda intended to help Trump win.

Meanwhile, Russia rejected allegations of meddling in the U.S. elections and Trump calls this entire episode a “hoax”.

Saudi Arabia to overhaul its cybersecurity preparedness: Potomac assessment

Saudi Arabia

Saudi Arabia, which is believed to be one of the most vulnerable nations to cyber attacks, is making efforts to improve its national-level cyber-preparedness, a Potomac assessment revealed. The Potomac Institute for Policy Studies (PIPS) recently published a report on “Saudi Arabia Cyber Readiness at a Glance” that provides an extensive analysis of the country’s cybersecurity-related efforts and capabilities,

SC Magazine quoted the report, saying Saudi Arabia is striving hard to achieve its ambitious goals for its Vision 2030 strategy. Vision 2030 emphasizes Saudi Arabia’s strategic location as the hub connecting Asia, Europe, and Africa.

According to Cyber Readiness Index (CRI) 2.0 methodology, Saudi Arabia’s newly-established Presidency of State Security aims to strengthen the country’s cyber resilience through following measures:

  • Developing and formalizing a national cybersecurity framework and strategy
  • Assigning clearly-defined roles and responsibilities to ministries and organizations
  • Promoting information sharing and collaboration
  • Building cybersecurity capability and increasing awareness

In 2011, the Ministry of Communications and Information Technology (MCIT) – one of the government agencies responsible for cybersecurity and digitization of government services in Saudi Arabia – began developing the country’s first “National Information Security Strategy (NISS).” While the strategy focusses on providing a secure and robust digital environment, it also points at cybersecurity skill gap in the country as a hindrance to achieve the desired goal.

To address the cybersecurity skill gap, the MCIT has launched talent development programs and partnerships with global IT companies to train more than 56,000 Saudi youths on key ICT skills between 2017 and 2020. It has also set up a National Information Technology Academy in collaboration with Saudi Aramco to train and develop Saudi talent.

In 2016, Saudi Arabia witnessed a slew of cyber attacks that had a huge impact on its government agencies and private sector companies. The Kingdom experienced around 1,000 cybersecurity attacks targeting critical infrastructure, seeking to steal data and causing services interruption.

Deloitte hacked! Attackers may have exposed sensitive information

Deloitte

One of the ‘big four’ accountancy firms, Deloitte, is the newest victim of a massive cyber attack. Confidential emails and “plans of some its blue-chip clients” were compromised, suggested a Guardian report. It also revealed that the attack went unnoticed for months.

The attackers had infiltrated the global email server through ‘administrator’s account’ which may mean that they had access to all areas of the server, including the restricted ones. Reports suggest that the company discovered the attack in March earlier this year, but the perpetrators may have penetrated into the systems way back in October 2016. The company has set up an internal review bench to investigate the incident.

Sources have revealed that the account only required a single password login and did not deploy two-step verification process. “Emails to and from Deloitte’s 244,000 staff were stored in the Azure cloud service, which was provided by Microsoft (…) In addition to emails, the Guardian understands the hackers had potential access to usernames, passwords, IP addresses, architectural diagrams for businesses and health information. Some emails had attachments with sensitive security and design details,” report suggested.

The company is also yet to establish the actor, which may have been a rogue hacker, a rival organization, or a state-sponsored activity. Sources have revealed that hackers weren’t able to cover their tracks, and reverse-engineering may help to understand the path the attacker took.

The first bell rang after Deloitte hired US law firm Hogan Lovells on “special assignment” to review “a possible cybersecurity incident” earlier this year. Deloitte confirmed to Guardian that the accounting firm has been a victim of a cyber attack, but “only a small number of its clients had been “impacted.” It would not be drawn on how many of its clients had data made potentially vulnerable by the breach.”

Reports also suggest that an estimated five million emails on cloud were accessed by the attacker/s. While Deloitte sternly stated the emails that were at risk were only a fraction of this number.

“In response to a cyber incident, Deloitte implemented its comprehensive security protocol and began an intensive and thorough review including mobilising a team of cybersecurity and confidentiality experts inside and outside of Deloitte,” a spokesman said. “As part of the review, Deloitte has been in contact with the very few clients impacted and notified governmental authorities and regulators. The review has enabled us to understand what information was at risk and what the hacker actually did, and demonstrated that no disruption has occurred to client businesses, to Deloitte’s ability to continue to serve clients, or to consumers. We remain deeply committed to ensuring that our cybersecurity defences are best in class, to investing heavily in protecting confidential information and to continually reviewing and enhancing cybersecurity. We will continue to evaluate this matter and take additional steps as required. Our review enabled us to determine what the hacker did and what information was at risk as a result. That amount is a very small fraction of the amount that has been suggested.”

Singapore on top in the list of “Attacking Countries:” Report

Singapore

When it comes to leading the world in launching cyber attacks, the island-nation Singapore has been ranked number one, as per a report published by an Israel-based multinational cybersecurity firm Check Point Software Technologies Ltd. In the list of “Attacking Countries,” Singapore features at the top outstripping superpower nations such as the U.S., the UK, Russia, Cyprus, Italy, France, China, Germany, and the Netherlands, the firm’s Threat map revealed.

Check Point tracks over 10 million global cyber attacks daily through its Threat map. It gathers the threat intelligence and distributes the same to customers for instant threat protection.

Eying Wee, Asia-Pacific spokesperson from Check Point, told The New Paper that even though the attacks are launched from computer systems in Singapore, the perpetrators behind these attacks hijack the vulnerable systems remotely. She explained that the high volume of Asia-based business traffic and massive computing power of the country makes it favorable for the hackers.

However, in the past, Singapore also witnessed cyber attacks on its government agencies, universities, and companies, before rising to pole position in the list of attacking countries.

Simultaneously, the list of top ten “Target Countries” was also released that features Colombia on top followed by India, Saudi Arabia, Ecuador, and Taiwan.

Earlier this year, a survey by United Nations International Telecommunication Union (ITU) revealed that Singapore has the best cybersecurity approach in the world. Singapore was named ahead of U.S., Malaysia, Oman, Estonia, Mauritius, Australia, Georgia, France, and Canada.

Singapore recently allocated S$1.5 million ($1.1 million) to train incident responders and operators to tackle cyber threats. The move was a part of ASEAN Cyber Capacity Building Program (ACCP) that endeavors to develop technical, policy, and strategy-building capabilities within ASEAN member states.

The newest ransomware authors are huge GoT fans

GOT

You may end up finding yourself amid the Dothrakis, unsullied, and three fully grown dragons if you fail to pay up. But, if you are a Lannister, who always pays his debts you may find yourself in a better proposition to handle the Locky ransomware. And even the other who haven’t understood the Game of Thrones references in the above lines, you must be beware of the Locky, a new ransomware that has been doing sporadic rounds. These are delivered in the email distributed campaign and even use Game of Thrones, a hit HBO fantasy series based on the novels my George RR Martin, A Song of Fire and Ice, references in its scripts.

In a blog spot, titled, “A Song of Ice and Ransomware: Game of Thrones References in Locky Phishing,” author Victor Cornell elaborated the Locky threat campaign, suggesting that the visual basic script of the phishing emails pays a tribute to Game of Thrones.

Variable names found in this VB script has characters of the TV series like Aria, SansaStark, RobertBaration, JohnSnow, or HoldTheDoor (aka Hodor).

“Lightweight script applications designed to deliver malware often use rotating or pseudorandom variable names to ensure that the malware delivery tools look unique. In this case, many of the variables (some misspelt) referred to characters and events from the globally-popular television fantasy epic Game of Thrones,” writes Victor Cornell, “Looking at this script offers some insight into what pop culture elements have influenced the threat actors. Like everyone else in modern society, they have interests and preferences, favorite music, movies, and television shows. The attackers allowed this to show through their selection of variable names.”

“The runtime for this script is indifferent to the variable names. The variable names could be anything, including completely random combinations of letters and numbers. However, the criminals responsible for this attack chose a distinctive theme for their variables, thereby revealing their interest in this pop culture phenomenon,” he notes.

Hackers may have been trading data from SEC breach

SEC

United States Securities and Exchange Commission (SEC) has revealed that its systems were breached last year and hackers have been illegally profiting from it. The announcement was made by SEC Chairman Jay Clayton in an eight-page statement where he majorly about SEC and cybersecurity with a passing reference toward the incident and the follow-up. “Notwithstanding our efforts to protect our systems and manage cybersecurity risk, in certain cases, cyber threat actors have managed to access or misuse our systems.  In August 2017, the Commission learned that an incident previously detected in 2016 may have provided the basis for illicit gain through trading,” he said.

“Specifically, a software vulnerability in the test filing component of our EDGAR system, which was patched promptly after discovery, was exploited and resulted in access to nonpublic information.  We believe the intrusion did not result in unauthorized access to personally identifiable information, jeopardize the operations of the Commission, or result in systemic risk.  Our investigation of this matter is ongoing, however, and we are coordinating with appropriate authorities.  As another example, our Division of Enforcement has investigated and filed cases against individuals who we allege placed fake SEC filings on our EDGAR system in an effort to profit from the resulting market movements.”

The statement did not speak about why the announcement was delayed by a year, or the exact date or the occurrence of the incident.

The incident comes to fore weeks after the major breach at credit-reporting firm Equifax, which has been served several class action lawsuits. The incident has brought the need for cybersecurity for organizations to the limelight. It also made several top-level reshuffles, Mark Rohrwasser has been appointed interim Chief Information Officer while Russ Ayres has been appointed interim Chief Security Officer.”

“This hack illustrates that protecting against hackers isn’t as easy as the government sometimes expects of companies,” said Bradley Bondi, a former SEC enforcement attorney now in private practice in an interview with Bloomberg Market. “Everyone is vulnerable at any time.”

Researchers spot Iranian cyber espionage campaign against Aerospace, Energy Firms

Log4j, Iranian Ransomware Actors, SpoofedSccholars, second-tier targets, NIOPDC

A recent investigation by cybersecurity vendor FireEye revealed that a sophisticated cyber espionage campaign was launched by an Iranian Advanced Persistent Threat group against the United States, Saudi Arabia, and South Korean organizations in aerospace and energy sectors. The campaign may have been run to gather information on aviation and petrochemical industries to improve Iran’s capabilities in these sectors.

The FireEye researchers said that the APT33 used a technique called spearphishing for the cyber espionage campaigns. The attackers used emails similar to the legitimate recruitment offers from valid employment websites and linking them to the malicious HTML application files. These spurious mails included a faked Equal Opportunity Employer disclosures from multiple websites posing as the domains of Boeing, Alsalam Aircraft Company, and Northrop Grumman Aviation Arabia. When opened, the documents were capable of dropping an APT33 custom backdoor on the attacked computer. The droppers used by the APT33 group include DROPSHOT and has links to a destructive data erasing tool SHAPESHIFT, used against Saudi Arabian targets. FireEye said that the SHAPESHIFT was not used for any attacks. However, DROPSHOT is known to be used only by the APT33.

The FireEye security analyst Jacqueline O’Leary told Dark Reading that at least six organizations, including a US aerospace company, a Saudi Arabian business group with interests in the aviation sector, and a South Korean company involved in petrochemicals and oil were targeted between May 2016 and August 2017. However, more organizations could have been targeted as well.

According to FireEye, the code found in one malware sample pointed out that it could be developed and launched by an individual who was working for the Iranian government previously. Other indicators to link Iran’s involvement in the campaigns include the use of artifacts written in Farsi, the country’s official language. The publicly available tools and backdoors were also found on the Iranian threat actor websites. The intentions for carrying out the cyber espionage also aligns with the national interest with activities coinciding with Iran’s work timings.

Josiah Kimble, a security analyst with FireEye, commented, “APT33 shares some similarities with other nation-state groups in that they rely on publicly available tools with some use of custom malware development, potentially suggesting the threat actors are a part of a greater capability. Like most suspected state-sponsored actors, APT33’s targeting of organizations most closely aligns with nation-state interests.”

Siemens and PAS announce strategic partnership to enhance industrial cybersecurity

Siemens

BUSINESS WIRE: Global engineering and technology firm Siemens and PAS Global, a provider of industrial control system (ICS) cybersecurity solutions, announced an agreement to provide fleet-wide, real time monitoring for control systems. The partnership will provide customers with deep analytics required to identify and inventory proprietary assets; and visibility to detect and respond effectively to attacks across the operating environment.

As the utilities and oil and gas sectors become increasingly digital to achieve revenue and efficiency gains, there is a corresponding need to identify cyber threats at their earliest stages – going beyond compliance regulations to secure operations. Organizations in these sectors must defend their entire digital footprint against persistent and highly sophisticated cyber threats without disrupting business processes.

According to recent research conducted by Ponemon Institute on the state of cybersecurity in the U.S. oil and gas industry, deployment of cybersecurity measures in the industry isn’t keeping pace with the growth of digitalization in oil and gas operations. Just 35 percent of survey respondents rate their organization’s OT cyber readiness as high. Sixty-eight percent of respondents say their organization experienced at least one cyber compromise, while 61 percent say their organization’s industrial control systems protection and security is not adequate.

The strategic partnership bridges the visibility gap for distributed, legacy control assets to provide a comprehensive view into fleet security. Focused on gathering detailed configuration data down to the sensor, the Siemens-PAS partnership will enable customers to secure proprietary systems in multi-vendor environments – guarding against cyber attacks as well as unauthorized engineering changes.

“Utilities and the oil and gas sector confront sophisticated, persistent and aggressive cyber threats in the operational environment. Enhanced fleet-wide visibility is critical to detecting attacks and anomalies at the earliest possible stage,” said Leo Simonovich, Siemens Vice President for Global Cyber Security. “With Siemens’ deep operational monitoring expertise and PAS’ leadership developing solutions to protect industrial control systems, this partnership is singularly-positioned to provide essential visibility, build a mindset of perpetual vigilance and ultimately strengthen the energy industry defenses.”

“With smarter, integrated automation comes a difficult challenge that has repercussions from the boardroom to facility operations: ICS cybersecurity,” says Eddie Habibi, founder and CEO of PAS Global. “It is generally well understood that you cannot secure what you cannot see. That is why accurate, up-to-date visibility of system inventory is a fundamental element of any cybersecurity solution. Our partnership with Siemens delivers a managed security service that covers the entire industrial enterprise.”

European Commission scales up EU’s response to cyber-attacks

EU

“In the past three years, we have made progress in keeping Europeans safe online. But Europe is still not well equipped when it comes to cyber-attacks. This is why, today, the Commission is proposing new tools, including a European Cybersecurity Agency, to help defend us against such attacks,” stated European Commission President Jean-Claude Juncker, in his annual State of the Union Address.

To equip Europe with the right tools to deal with cyber-attacks, the European Commission and the High Representative are proposing a wide-ranging set of measures to build strong cybersecurity in the EU. This includes a proposal for an EU Cybersecurity Agency to assist Member States in dealing with cyber-attacks, as well as a new European certification scheme that will ensure that products and services in the digital world are safe to use.

Federica Mogherini, High Representative/Vice-President, said: “The EU will pursue an international cyber policy promoting an open, free and secure cyberspace as well as support efforts to develop norms of responsible state behaviour, apply international law and confidence building measures in cybersecurity.”

Andrus Ansip, Vice-President for the Digital Single Market, said: “No country can face cybersecurity challenges alone. Our initiatives strengthen cooperation so that EU countries can tackle these challenges together. We also propose new measures to boost investment in innovation and promote cyberhygiene”

Julian King, Commissioner for the Security Union, said: “We need to work together to build our resilience, to drive technological innovation, to boost deterrence, reinforcing traceability and accountability, and harness international cooperation, to promote our collective cybersecurity.”

Mariya Gabriel, Commissioner for the Digital Economy and Society, said: “We need to build on the trust of our citizens and businesses in the digital world, especially at a time when large-scale cyber-attacks are becoming more and more common. I want high cybersecurity standards to become the new competitive advantage of our companies.”

With recent ransomware attacks, a dramatic rise in cyber-criminal activity, the increasing use of cyber tools by state actors to meet their geopolitical goals and the diversification of cybersecurity incidents, the EU needs to build a stronger resilience to cyber-attacks and create an effective EU cyber deterrence and criminal law response to better protect Europe’s citizens, businesses and public institutions. This is what today’s Cybersecurity Package is about.

Building EU resilience: A strong EU Cybersecurity Agency

An EU Cybersecurity Agency: Building on the existing European Agency for Network and Information Security (ENISA), the Agency will be given a permanent mandate to assist Member States in effectively preventing and responding to cyber-attacks. It will improve the EU’s preparedness to react by organising yearly pan-European cybersecurity exercises and by ensuring better sharing of threat intelligence and knowledge through the setting up of Information Sharing and Analyses Centres. It will help implement the Directive on the Security of Network and Information Systems which contains reporting obligations to national authorities in case of serious incidents.

The Cybersecurity Agency would also help put in place and implement the EU-wide certification framework that the Commission is proposing to ensure that products and services are cyber secure. Just as consumers can trust what they eat thanks to EU food labels, new European cybersecurity certificates will ensure the trustworthiness of the billions of devices (“Internet of Things”) which drive today’s critical infrastructures, such as energy and transport networks, but also new consumer devices, such as connected cars. Cybersecurity certificates will be recognised across Member States, thereby cutting down on the administrative burden and costs for companies.

Stepping up the EU’s cybersecurity capacity

It is in the EU’s strategic interest to ensure that the technological tools of cybersecurity are developed in a way that allows the digital economy to flourish, while also protecting our security, society and democracy. This includes the protection of critical hardware and software. To reinforce the EU’s cybersecurity capacity, the Commission and the High Representative are proposing:

  • A European Cybersecurity Research and Competence Centre(pilot to be set up in the course of 2018). Working with Member States, it will help develop and roll out the tools and technology needed to keep up with an ever-changing threat and make sure our defences are as state-of-the-art as the weapons that cyber-criminals use. It will complement capacity-building efforts in this area at EU and national level.
  • A Blueprint for how Europe and Member States can respond quickly, operationally and in unison when a large-scale cyber-attack strikes. The proposed procedure is laid down in a Recommendation adopted last week. The Recommendation also asks Member States and EU institutions to establish an EU Cybersecurity Crisis Response Framework to make the Blueprint operational. It will regularly be tested in cyber and other crisis management exercises.
  • More solidarity: In the future, the possibility of a new Cybersecurity Emergency Response Fund could be considered for those Member States that have responsibly implemented all the cybersecurity measures required under EU law. The Fund could provide emergency support to help Member States – just as the EU’s Civil Protection Mechanism is used to help with cases of forest fires or natural disasters.
  • Stronger cyber defence capabilities: Member States are encouraged to include cyber defence within the Framework of Permanent Structured Cooperation (PESCO) and the European Defence Fund to support cyber defence projects. The European Cybersecurity Research and Competence Centre could also be further developed with a cyber defence dimension. To address the skills gap in cyber defence, the EU will create a cyber defence training and education platform in 2018. The EU and NATO will together foster cyber defence research and innovation cooperation. Cooperation with NATO, including participation in parallel and coordinated exercises, will be deepened.
  • Enhanced international cooperation: The EU will strengthen its response to cyber-attacks by implementing the Framework for a Joint EU Diplomatic Response to Malicious Cyber Activities, supporting a strategic framework for conflict prevention and stability in cyberspace. This will be coupled with new cyber capacity building efforts to assist third countries to address cyber threats.

 

Creating an effective criminal law response

A more effective law enforcement response focusing on detection, traceability and the prosecution of cyber criminals is central to building an effective disincentive to commit such crimes. The Commission is therefore proposing to boost deterrence through new measures to combat fraud and the counterfeiting of non-cash means of payment.

The proposed Directive will strengthen the ability of law enforcement authorities to tackle this form of crime by expanding the scope of the offences related to information systems to all payment transactions, including transactions through virtual currencies. The law will also introduce common rules on the level of penalties and clarify the scope of Member States’ jurisdiction in such offences.

To step up effective investigation and prosecution of cyber-enabled crime, the Commission will also present proposals to facilitate cross-border access to electronic evidence in the beginning of 2018. In addition, by October, the Commission will present its reflections on the role of encryption in criminal investigations.

 

Germany has seen no sign of election meddling until now

Germany elections

Elections hacks are now a hot fuss. The juggernaut began rolling with the United States presidential elections in 2016 which continued till the recent French elections where president Emmanuel Macron’s emails were leaked. The scenario had given nations apprehension over the state of affairs of the election process and Germany was soon to join the bandwagon with its parliamentary elections scheduled on September 24, 2017. The country was warned by allies about possible foreign meddling. All hands were on the deck, and BSI federal cyber protection agency kept a close watch on possible efforts to influence the election from other nations.

It may come as a relief that until now German government officials and security experts have not seen signs of hacking or suspicious news leaks. “We have no indications of any new incidents or attacks in connection with the federal election,” a BSI spokesman told Reuters.

Credits also go to German political parties who had agreed not to play up any fake news or embarrassing information. According to Tyson Barker, a fellow at the German arm of the U.S.-based Aspen Institute think tank, “There is a stronger cohesion … within the German political class to make sure that this is not impactful on the election results if it were to come to pass.”

BSI was also instrumental in closing the security gaps in the vote-tabulating software. According to a release, German hacker association Chaos Computer Club (CCC) had claimed that the PC-Wahl version 10 software, used in Germany during elections to count and distribute voting results, contained serious vulnerabilities. The group said that the attackers can secretly modify vote totals before they are reported to electoral officers. The CCC said, “The analysis shows a host of problems and security holes, to an extent where public trust in the correct tabulation of votes is at stake.”

The CCC spokesperson Linus Neumann, said, “The amount of vulnerabilities and their severity exceeded our worst expectations. A whole chain of serious flaws, from the update server, via the software itself through to the election results to be exported allows for us to demonstrate three practical attack scenarios in one.”

Barker called it a wake-up call, “Just because we’re doing this on paper doesn’t mean that from end to end there is protection throughout the process as far as tabulating results,” he said. Vote IT GmbH, maker of a vote collation software also implemented a series of BSI recommendations to make the electoral process safe and hack proof.